Here are the elements you need to perform that configuration To allow a internal user to establish a Nortel Extranet VPN session through my FW-1. I have some documentation that says to configure these 3 ports: UDP 500 for IKE Key Management IP Protocol 50 for IPSEC Payload Encryption IP Protocol 51 for IPSEC Authentication Header To set this up you should authorize the services IKE,, AH and ESP.
Christian ALT Telecom and Logistics Associates Network and Security Company Firewall-1 FAQ http://www.tla.ch/TLA/FW/FW1FAQ.html -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Behalf Of Ilia Shapira Sent: dimanche, 25. janvier 2004 09:31 To: [EMAIL PROTECTED] Subject: [FW-1] Access to Nortel Contivity VPN behind CP NG I have a PC behind our CP NG that need to connect to some Nortel Contivity VPN, Nortel say that I need to open pot 500. I added a rule to allow IPSEC that include IKE that is port 500 however I still can't connect? Anyone have an idea what else do I need to do? Does it have something to do with the fact that this PC is behind NAT ? Thank you. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= --- Incoming mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004 ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
